PuTTY update instantly and change keys

The free software PuTTY can be used to create Secure Shell, Telnet, remote login, or serial interfaces to a server. However, there is a critical vulnerability in the software in question (CVE-2024-31497) that can be used to reconstruct SSH private keys. PuTTY versions 0.68 to 0.80 as well as other products (for example FileZilla) are directly affected by the vulnerability. putty

The downside is that simply updating the products is not enough, as the keys may already be leaked.

Discover more articles in search results.

PuTTY is free software for establishing connections via Secure Shell (SSH), Telnet, etc. It acts as a client and establishes the connection to a server. When the connection is established, the user's identity is verified using one of the provided authentication methods.
PuTTY versions 0,68 through 0,80 contain the critical vulnerability (CVE-2024-31497), which allows attackers to reconstruct the NIST P-521 private key using approximately 60 signatures. The vulnerability was discovered by Fabian Bäumer and Marcus Brinkmann (Ruhr University Bochum).

If you are interested in more details you can read the announcement at NIST.

https://nvd.nist.gov/vuln/detail/CVE-2024-31497


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).